CVE-2026-105845: Payload: SQL Injection in SQLite and Postgres
Impact A user can submit a request that exploits a SQL Injection vulnerability in Payload.
You are affected if: - You use an affected Payload version. - Untrusted users can query readable collections using dynamic filters or joins.
You are not affected if you use MongoDB (@payloadcms/mongodb).
Patches Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
Workarounds Upgrading to a patched version is recommended. Until you can upgrade, restrict untrusted users from supplying dynamic query filters or join parameters and limit read access to affected collections.
Other sources
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.27 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.88.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.88.0 - Compensating control
Restrict untrusted users from supplying dynamic query filters or join parameters, and limit read access to affected collections.
Event History
Frequently Asked Questions
Which deployments are affected?
Payload CMS versions from 3.0.0 before 3.88.0 are affected, as are canary releases before 4.0.0-canary.27, when using the SQLite or Postgres adapters.
What access does an attacker need?
An attacker must be an untrusted user able to query readable collections through dynamic filters or joins. No other prerequisites are specified in the available information.
Are default deployments necessarily vulnerable?
The issue depends on the application exposing readable collections to untrusted users through dynamic filters or joins. The available information does not establish whether this exposure exists in a default configuration.
What versions fix the issue?
Upgrade to Payload CMS 3.88.0 or later, or to 4.0.0-canary.27 or later for the canary release line.